Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20190430084031.uj3462xm5drpdqmk@lorien.valinor.li>
Date: Tue, 30 Apr 2019 10:40:31 +0200
From: Salvatore Bonaccorso <carnil@...ian.org>
To: oss-security@...ts.openwall.com
Subject: Re: Linux kernel: multiple issues

Hi,

On Mon, Apr 29, 2019 at 09:15:28PM +0200, Salvatore Bonaccorso wrote:
> Hi Jann,
> 
> On Mon, Apr 29, 2019 at 02:56:06PM -0400, Jann Horn wrote:
> > == missing locking between ELF coredump code and userfaultfd VMA modification ==
> > https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=04f5866e41fb70690e28397487d8bd8eea7d712a
> > https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.114
> > https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.37
> > https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.10
> > https://bugs.chromium.org/p/project-zero/issues/detail?id=1790
> > CVE-2019-11599
> 
> If I'm not mistaken, this was assigned already CVE-2019-3892,
> information from https://bugzilla.redhat.com/show_bug.cgi?id=1696015

FTR, CVE-2019-11599 was kept and CVE-2019-3892 REJECTed as reservation
duplicate of CVE-2019-11599.

Regards,
Salvatore

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.